Monday, June 27, 2016

Fasterized Phishing Fail

Hi all, so this a quick and short post about an epic fail involving a bank, AV vendors and SaaS provider.

So, im minding my own business, thinking to go phishing some new shizzle, and all of the sudden le wild credit-agricole phish appears


checking VT and a whopping 10/67 results say this a phish! hide yo kids, hide yo pass
so me, as kind of n00b, thought, hey those people at those vendors have more experience, they must know what they talking about.
so i started to snoop around as that domain shadowing seemed quite interesting.
apparently the AV vendors dont know what they are doing, its either the horde detection, or bad detection algorithm, because as soon as i checked what it is i immediately found those funny domains belong to fasterize a service that act as a smart proxy for your site to reduce bandwidth and reduce load times of the pages, apparently it also the fast track to get your site blacklisted for "phishing" because the url mimic the real credit-agricole site.

conclusion, blacklisting is crap, there always will be another bad domain, but whitelisting would save the embarrassment here, i think fasterize is a new service and they should communicate with AV vendors with aggressive blacklists if they want to offer their service to banks.

bonus: they need to update their certificate



Tuesday, May 17, 2016

Android super charge crap lockscreen

its been a while, quite busy with... stuff...
but here is a quick post about something annoying.
after i have updated several apps on my android phone, suddenly i noticed a weird lock screen.
my first reaction was WTF, because after i swiped, my original lock screen appeared.
so i looked at list of updated applications, looked at all my installed apps, but nothing was really standing out.
so i looked in google, and it is appears to be a new trend for unknown reason.

here are few links:

http://forums.androidcentral.com/samsung-galaxy-s6-edge/512443-charging-screen-question.html
http://forums.androidcentral.com/samsung-galaxy-note-4/640251-new-speed-charge-battery-status-lock-screen-annoying-ads-just-appeared-gn4-2.html
http://android.stackexchange.com/questions/143330/what-is-this-lock-screen-with-ads-and-how-do-i-remove-it
http://androidforums.com/threads/speed-charge-on-lock-screen.1010631/
https://www.reddit.com/r/Android/comments/4g8hbq/psa_amber_weather_widget_223_adds_du_quick_charge/
https://www.reddit.com/r/galaxynote5/comments/45ahkp/wtf_the_ads_showing_on_the_charging_lock_screen/

and i even spotted one of the apps that have been updated to be on this thread:

https://www.reddit.com/r/nexus6/comments/4ilwcl/ive_had_my_nexus_6_since_release_today_it_asked/

so, i was quite confident this wasn't some malware (although i don't have anything worthy on my phone) and in the worst case im suffering some excessive battery drain (all those apps are fake shit, i hope you know that) and maybe i will get some ads, although i didnt get any :<

the easiest solution was of course just to uninstall the shit and see how it goes, but i decided to be more technical, and try to do some adb shell "magic" :


adb shell dumpsys window windows | grep -E 'mCurrentFocus|mFocusedApp'
so... it was indeed the photo editor...

here are some pictures of this magnificent app:



i must say that the settings actually worked, and it disabled that lock screen, and right after that i uninstalled it.

another note: the lock screen would appear only when the phone is charging (so you could  get the super duper mega fast charge boost)